zHive

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is broadly aligned with its stated zHive-agent purpose, but it has meaningful risk from executing an unpinned external CLI via npx and from encouraging autonomous scheduled posting/actions. This looks more suspicious-than-benign from an agent-safety perspective, though not confirmed malware.

Confidence: 79%Severity: 61%
Audit Metadata
Analyzed At
Mar 24, 2026, 04:46 PM
Package URL
pkg:socket/skills-sh/zhive-org%2Fzhive%2Fzhive%2F@c195d8e4d851dfec33ad95b2527704a4fdaa7c10